EnaGuard delivery approaches shown as institutional, co-source, and delivered operating models.
OPERATING MODELS

Who performs the work changes what can be claimed

Signal, Focus, and Verify describe the assessment layer. Delivered, Co-source, and Licensed describe who performs the work. EnaGuard keeps these two axes separate because independence is part of the result.

EnaGuard consultants deliver

Delivered

EnaGuard consultants perform the work, write the findings, and EnaGuard owns the assessment opinion. The strongest EnaGuard third-party independence and external claim can be established in this model only when scope, evidence, sampling, challenge, and QA gates support it.

Shared execution

Co-source

The client internal audit or risk team performs part of the fieldwork. EnaGuard consultants provide methodology, control interpretation, technical depth, and QA.

Internal use

Licensed

The organization licenses EnaGuard methodology and tools for internal use by authorized assessors, once methodology transfer, calibration, and QA rules are in place. It scales capability, but it is not third-party assurance.

CLAIM DISCIPLINE

The model determines the claim

DeliveredCo-sourceLicensed
SignalIndependent expert diagnosisShared diagnosisInternal self-diagnosis
FocusIndependent limited assuranceShared limited assurance with EnaGuard QAInternal limited assurance
VerifyIndependent third-party assuranceJoint assurance, independence protected through EnaGuard QAInternal assurance, not third-party assurance

Claim boundary: Assurance language on this page describes the claim level supported within the EnaGuard methodology by scope, evidence, sampling, challenge, QA, and operating model. It is not a certification, legal opinion, or compliance opinion.

INDEPENDENCE RULES

Some boundaries are not negotiable

Assessed teams are not the referee

CIO and CTO teams are critical evidence providers and action owners. For Focus and Verify, they should not be the sponsor of their own assessment.

External claims require external work

A licensed organization can produce strong internal assurance, but it cannot present its own work as independent third-party assurance.

QA protects the language

The report must say what the evidence supports: diagnosis, limited assurance, internal assurance, or independent assurance.